Cisco Linksys E1500/E2500 Router Multiple Security Vulnerabilities
BID:57760
Info
Cisco Linksys E1500/E2500 Router Multiple Security Vulnerabilities
| Bugtraq ID: | 57760 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 06 2013 12:00AM |
| Updated: | Apr 02 2013 04:17PM |
| Credit: | Michael Messner |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco Linksys E1500/E2500 Router Multiple Security Vulnerabilities
Cisco Linksys E1500/E2500 routers are prone to the following security vulnerabilities:
1. A command-execution vulnerability
2. A security-bypass vulnerability
3. A cross-site request-forgery vulnerability
4. A cross-site scripting vulnerability
5. A directory-traversal vulnerability
6. A URI-redirection vulnerability
An attacker can exploit these issues to execute arbitrary commands, perform phishing attacks by redirecting a user to a potentially malicious site, bypass certain security restrictions, steal cookie-based authentication credentials, gain access to system and other configuration files, or perform unauthorized actions in the context of a user session.
Cisco Linksys E1500/E2500 routers are prone to the following security vulnerabilities:
1. A command-execution vulnerability
2. A security-bypass vulnerability
3. A cross-site request-forgery vulnerability
4. A cross-site scripting vulnerability
5. A directory-traversal vulnerability
6. A URI-redirection vulnerability
An attacker can exploit these issues to execute arbitrary commands, perform phishing attacks by redirecting a user to a potentially malicious site, bypass certain security restrictions, steal cookie-based authentication credentials, gain access to system and other configuration files, or perform unauthorized actions in the context of a user session.
Exploit / POC
Cisco Linksys E1500/E2500 Router Multiple Security Vulnerabilities
An attacker can exploit these issues through a browser. To exploit cross-site scripting and cross-sire request-forgery issues, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following exploit code and example data are available:
An attacker can exploit these issues through a browser. To exploit cross-site scripting and cross-sire request-forgery issues, the attacker must entice an unsuspecting victim to follow a malicious URI.
The following exploit code and example data are available:
Solution / Fix
Cisco Linksys E1500/E2500 Router Multiple Security Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Cisco Linksys E1500/E2500 Router Multiple Security Vulnerabilities
References:
References: